All stories

Attackers exploit maximum severity ColdFusion flaw to execute arbitrary code on target systems

Attackers are actively exploiting a maximum-severity path traversal vulnerability in Adobe ColdFusion to execute arbitrary code. CISA has ordered federal agencies to patch their systems by Friday, June 10, due to the high risk of automated, large-scale attacks. Update your ColdFusion instances immediately.

Summary

A critical security flaw in Adobe ColdFusion is being actively exploited in the wild, allowing remote attackers to gain control over unpatched systems. The vulnerability, identified as CVE-2026-48282, stems from an improper limitation of a pathname to a restricted directory. This path traversal weakness enables threat actors to execute arbitrary code within the context of the current user without requiring any user interaction.

The Cybersecurity and Infrastructure Security Agency (CISA) added the flaw to its Known Exploited Vulnerabilities catalog on July 7, 2026. In response, CISA has issued a directive for U.S. Federal Civilian Executive Branch (FCEB) agencies to apply patches by Friday, June 10, under Binding Operational Directive 26-04.

Technical details

The vulnerability is a path traversal flaw (CWE-22) that occurs when the application fails to properly restrict access to certain directories. By manipulating file paths, an attacker can move outside of intended directories to access restricted areas of the file system.

Successful exploitation results in arbitrary code execution. Because the attack does not require user interaction and can be performed by a remote actor without existing privileges, it poses a high risk for automated exploitation. The impact is considered total, as it allows attackers to execute commands with the permissions of the ColdFusion service.

Affected products and fixed versions

The vulnerability impacts several versions of Adobe's web development and marketing automation platforms.

Product Affected Versions
Adobe ColdFusion 2025 2025.9 and earlier
Adobe ColdFusion 2023 2023.20 and earlier
Adobe Campaign Classic v7: 7.4.3 build 9396 and prior

Adobe released security updates on June 30, 2026, to address this flaw along with six other maximum-severity vulnerabilities in ColdFusion and Campaign Classic. While Adobe stated they were not aware of exploits for the other six issues at the time of release, KEVIntel founder Ryan Dewhurst reported that exploitation of CVE-2026-48282 began within two hours of the disclosure.

Why this matters for defenders

The speed of exploitation in this instance is significant. Attackers moved against the vulnerability almost immediately after the security patches were made public. For organizations running ColdFusion, the window for defense is extremely narrow.

Shadowserver currently tracks nearly 800 Adobe ColdFusion instances exposed to the internet. While it is unknown how many of these are honeypots or have already been secured, any exposed instance represents a potential target for remote code execution. Because the attack can be automated, large-scale scanning and exploitation attempts are highly likely.

Defender guidance

Prioritize patching all ColdFusion instances immediately. If you cannot apply the patch within 72 hours, evaluate your internet exposure and consider moving the service behind additional layers of security or discontinuing use if mitigations are unavailable.

Federal agencies must adhere to the timelines established in Binding Operational Directive 26-04, which prioritizes vulnerabilities that can be automated for large-scale attacks or grant total control over a device. For non-federal entities, the priority remains high due to the active exploitation reported by the Canadian Center for Cyber Security (CCCS) and other security researchers.

Sources

  1. https://www.bleepingcomputer.com/news/security/cisa-orders-feds-to-patch-max-severity-coldfusion-flaw-by-friday/
  2. https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-48282
  3. https://nvd.nist.gov/vuln/detail/CVE-2026-48282
  4. http://www.cyber.gc.ca/en/alerts-advisories/adobe-security-advisory-av26-647
Harith Dilshan

Harith Dilshan

- Offensive Security Engineer | Ethical Hacker | Penetration Tester -